ZeroHour

CVE-2026-19766

niche

Authentication Bypass Leads to Privileged RCE in HPE Aruba Networking Fabric Composer

CVSS 3.1
9.6 critical
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-19766 is an improper authentication flaw (CWE-287) in the underlying operating system of HPE Aruba Networking Fabric Composer (AFC), HPE's data center fabric orchestration appliance/software. An unauthenticated attacker positioned on an adjacent network segment (e.g., the same management or fabric network) can bypass authentication and execute arbitrary code as a privileged user on the underlying OS. Successful exploitation results in complete compromise of the AFC host, including full confidentiality, integrity, and availability impact per the CVSS scope-changed rating of 9.6 (critical). Only organizations running HPE Aruba Networking Fabric Composer are affected, and because the attack vector is adjacent rather than internet-facing, exposure is largely limited to those with untrusted access to AFC's network environment. No public proof-of-concept, KEV listing, or known exploitation exists, and EPSS currently assigns a low 0.3% probability of exploitation within 30 days.

What to do: Check HPE's security bulletin (HPE Security Alert) for this CVE and upgrade Fabric Composer to the fixed release it specifies, as affected/fixed versions are not listed here. In the interim, restrict access to the AFC management and fabric networks to trusted operators and isolate the underlying OS interfaces from untrusted adjacent segments. Monitor HPE advisories for updated guidance, since no public exploit or in-the-wild exploitation has been reported.

Affected
arubanetworks (HPE) HPE Aruba Networking Fabric Composer
Estimated exposure
nichelikely low thousands of AFC host deployments worldwide (specialized data center fabric-management appliance) — Fabric Composer is a niche data center orchestration product deployed only alongside HPE Aruba Networking data center switching and HPE compute, so the install base is far smaller than mainstream Aruba networking lines, and the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.

Vendors
arubanetworks
Products
fabric composer
Weakness
CWE-287
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.